ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ26ÖÜ

Ðû²¼Ê±¼ä 2018-07-02

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


        2018Äê06ÔÂ25ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSchneider Electric U.motion BuilderÕ»»º³åÇøÒç³ö©¶´ £»Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³ö©¶´ £»Adobe Reader DCÔ½½ç¶ÁÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Microsoft OneDrive DLL´¦ÖÃÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Apache HBaseÄþ¾²ÏÞÖÆÈƹý©¶´ ¡£

 

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±¾¯¸æ³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤ £»Ó¢¹úË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓû§µÄÓïÒô¼Ç¼ £»Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬¿É½øÒ»²½Ìá¸ßÍøÂçÄþ¾²ÐÔ £»FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶ £»FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ ¡£

 

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£

 

¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1¡¢Schneider Electric U.motion BuilderÕ»»º³åÇøÒç³ö©¶´

 

        Schneider Electric U.motion Builder´æÔÚÕ»µÄ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.schneiderelectric.com/en/download/document/Umotion_Server_update/


2¡¢Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³ö©¶´

 

        Delta Industrial Automation COMMGR AHSIM_5x0 Simulator´¦ÖÃTCP±¨ÎÄ´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔCOMMGR½ø³ÌÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

       

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.deltaww.com/Products/PluginWebUserControl/downloadCenterCounter.aspx?DID=2093&DocPath=1&hl=en-US

3¡¢Adobe Reader DCÔ½½ç¶ÁÈÎÒâ´úÂëÖ´ÐЩ¶´

 

        Adobe Reader DC´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPDFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£

      

  Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-02.html
4¡¢Microsoft OneDrive DLL´¦ÖÃÈÎÒâ´úÂëÖ´ÐЩ¶´

 

        Microsoft OneDrive´¦ÖÃËÑË÷·¾¶´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄDLL£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://blogs.technet.microsoft.com/srd/2018/04/04/triaging-a-dll-planting-vulnerability/


5¡¢Apache HBaseÄþ¾²ÏÞÖÆÈƹý©¶´

        Apache HBase´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷ ¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96@%3Cdev.hbase.apache.org%3E

 

Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÈËÔ±¾¯¸æ³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


       

 

 SANS¼¼ÊõÑо¿ÔºÔº³¤Johannes Ullrich³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤ ¡£¹¥»÷ÕßÊ×ÏÈÈëÇÖWordPress»òDrupalµÈCMS¹¹½¨µÄÍøÕ¾£¬È»ºó´´½¨NetflixµöÓãÍøÕ¾²¢»ñÈ¡ÓëNetflixÃû³ÆÏà¹ØµÄTLSÖ¤Ê飬Èçnetflix.domain.com»ònetflix.login.domain.com£¬ÕâʹÆä¿´ÆðÀ´Ô½·¢¿ÉÐÅ ¡£ËäÈ»NetflixÕË»§¼ÛÖµ²¢²»¸ß£¬µ«ÕâÖÖ¹¥»÷Ò×ÓÚʵÏÖ×Ô¶¯»¯ÇÒÄÑÒÔÈÃÊܺ¦Õß·¢ÏÖ ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/new-phishing-scam-reels-in-netflix-users-to-tls-certified-sites/132976/

 

2¡¢Ó¢¹úË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓû§µÄÓïÒô¼Ç¼

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Òþ˽± £»¤×éÖ¯Big Brother Watch·¢ÏÖÓ¢¹úµÄË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓ¢¹ú¹«ÃñµÄÓïÒô¼Ç¼ ¡£HMRCͨ¹ý2017Äê1ÔÂÍƳöµÄÒ»ÏîÓïÒôʶ±ð·þÎñÊÕ¼¯ÁËÕâЩ¼Ç¼£¬¸Ã·þÎñÔÊÐíÓû§ÔÚºô½ÐHMRCʱͨ¹ýÓïÒô½øÐÐÉí·ÝÑéÖ¤ ¡£µ«Big Brother Watch·¢ÏÖÓû§ÎÞ·¨Ñ¡Ôñ²»Ê¹Óø÷þÎñ£¬ËùÓв¦´òHMRCÈÈÏßµÄÓû§¶¼±»ÆȼÖÆÁËÓïÒô¼Ç¼£¬¶øÇÒÓû§ÎÞ·¨Ñ¡Ôñ´ÓHMRCµÄÊý¾Ý¿âÖÐɾ³ýÆäÓïÒô¼Ç¼ ¡£¸Ã×éÖ¯ÈÏΪHMRC´Ë¾ÙÃ÷ÏÔÎ¥·´ÁËGDPR£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒѶԴËÊÂÕ¹¿ªÕýʽµÄÊÓ²ì ¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/uk-tax-agency-recorded-the-voices-of-51-million-brits/

 

3¡¢Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬¿É½øÒ»²½Ìá¸ßÍøÂçÄþ¾²ÐÔ

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
       

±¾ÖÜÒ»Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬WPA3ÊÇÓÃÓÚWi-FiÁ¬½ÓµÄÓû§Éí·ÝÑéÖ¤¼¼ÊõµÄ×îа汾 ¡£WPA3ÓÐÁ½ÖÖÄþ¾²Ä£Ê½£¬WPA3-PersonalºÍWPA3-Enterprise£¬ÕâÁ½ÖÖÄþ¾²Ä£Ê½µÄÖ÷ÒªÇø±ðÔÚÓÚÉí·ÝÑéÖ¤½×¶Î ¡£¶ÔÓÚÆóÒµ¡¢Õþ¸®ºÍ½ðÈÚÍøÂçÖÐʹÓõÄÉ豸£¬½¨ÒéʹÓÃWPA3-EnterpriseÄþ¾²Ä£Ê½£¬WPA3-PersonalÔòÊÇÃæÏòÆÕͨ¸öÈËÓû§ ¡£Wi-FiÁªÃËÌåÏÖWPA3µÄSAEËã·¨Äܹ»µÖÓù±©Á¦¹¥»÷£¬WPA3½«ÔÚ¶à´Îʧ°ÜʵÑéºó×èÖ¹ÈÏÖ¤ÇëÇó ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-wpa3-wi-fi-standard-released/

 

4¡¢FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



       

°ÍÀè¾ÆµêÔ¤¶©¹«Ë¾FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶ ¡£FastBooking³Æ¹¥»÷ÕßÔÚ6ÔÂ14ÈÕÀûÓÃÆä·þÎñÆ÷ÉÏÒ»¸öÈí¼þµÄ©¶´°²×°Á˶ñÒâÈí¼þ£¬²¢ÇÔÈ¡Á˾ƵêÓû§µÄÐÕÃû¡¢¹ú¼®¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍ¾ÆµêÔ¤¶¨Ïà¹ØÐÅÏ¢£¨¾ÆµêÃû³Æ¡¢ÈëסºÍÍË·¿£©µÈÊý¾Ý£¬ÇÔÈ¡µÄÊý¾Ý»¹°üÂÞ²¿ÃÅÓû§µÄÒøÐп¨ÐÅÏ¢£¬È翨ºÅ¡¢¹ýÆÚÈÕÆÚµÈ ¡£FastBooking³Æ¸ÃʼþÓ°ÏìÁËÈÕ±¾µÄ380¼Ò¾Æµê£¬Bleeping ComputerÈÏΪÕâÒ»Êý×ÖÔÚÈ«Çò·¶Î§ÄÚ¿ÉÄÜÁè¼ÝÁË1000 ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hundreds-of-hotels-affected-by-data-breach-at-hotel-booking-software-provider/

 

5¡¢FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



 Ñо¿ÈËÔ±Inti De Ceukelaire·¢ÏÖµÚÈý·½ÖÇÁ¦¾ºÈüÓ¦ÓÃNametests.comʹԼ1.2ÒÚFacebookÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ ¡£Ö»ÒªFacebookÓû§ÔÚNameTestsÍøÕ¾ÉÏ×¢²á£¬¸Ã¹«Ë¾½«¿ÉÒÔ»ñÈ¡Óû§µÄ¸öÈËÊý¾Ý ¡£µ«Ñо¿ÈËÔ±·¢ÏÖNameTestsÍøÕ¾´íÎóµØ½«Æä¡°Access-Control-Allow-Origin¡±¼ÆıÅäÖóÉͨÅä·û*£¬ÕâÔÊÐíÈκÎÍøÕ¾·ÃÎÊÆä×ÊÔ´£¬°üÂÞÕâЩÓû§µÄ¸öÈËÊý¾Ý ¡£NameTestsÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/facebook-users-data-leak.html

 

©ADLab ¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ 2016